--- loncom/lonnet/perl/lonnet.pm 2000/05/01 20:19:38 1.12 +++ loncom/lonnet/perl/lonnet.pm 2000/08/14 21:40:46 1.23 @@ -4,26 +4,47 @@ # Functions for use by content handlers: # # plaintext(short) : plain text explanation of short term -# allowed(short,url) : returns codes for allowed actions +# allowed(short,url) : returns codes for allowed actions F,R,S,C +# definerole(rolename,sys,dom,cou) : define a custom role rolename +# set priviledges in format of lonTabs/roles.tab for +# system, domain and course level, +# assignrole(udom,uname,url,role,end,start) : give a role to a user for the +# level given by url. Optional start and end dates +# (leave empty string or zero for "no date") +# assigncustomrole (udom,uname,url,rdom,rnam,rolename,end,start) : give a +# custom role to a user for the level given by url. +# Specify name and domain of role author, and role name +# revokerole (udom,uname,url,role) : Revoke a role for url +# revokecustomrole (udom,uname,url,rdom,rnam,rolename) : Revoke a custom role # appendenv(hash) : adds hash to session environment # store(hash) : stores hash permanently for this url # restore : returns hash for this url # eget(namesp,array) : returns hash with keys from array filled in from namesp # get(namesp,array) : returns hash with keys from array filled in from namesp # put(namesp,hash) : stores hash in namesp +# dump(namesp) : dumps the complete namespace into a hash +# ssi(url,hash) : does a complete request cycle on url to localhost, posts +# hash +# repcopy(filename) : replicate file +# dirlist(url) : gets a directory listing # # 6/1/99,6/2,6/10,6/11,6/12,6/14,6/26,6/28,6/29,6/30, # 7/1,7/2,7/9,7/10,7/12,7/14,7/15,7/19, # 11/8,11/16,11/18,11/22,11/23,12/22, # 01/06,01/13,02/24,02/28,02/29, # 03/01,03/02,03/06,03/07,03/13, -# 04/05 Gerd Kortemeyer +# 04/05,05/29,05/31,06/01, +# 06/05,06/26 Gerd Kortemeyer +# 06/26 Ben Tyszka +# 06/30,07/15,07/17,07/18,07/20,07/21,07/22,07/25 Gerd Kortemeyer +# 08/14 Ben Tyszka package Apache::lonnet; use strict; use Apache::File; use LWP::UserAgent(); +use HTTP::Headers; use vars qw(%perlvar %hostname %homecache %spareid %hostdom %libserv %pr %prp $readit); use IO::Socket; @@ -284,7 +305,9 @@ sub subscribe { sub repcopy { my $filename=shift; + $filename=~s/\/+/\//g; my $transname="$filename.in.transfer"; + if ((-e $filename) || (-e $transname)) { return OK; } my $remoteurl=subscribe($filename); if ($remoteurl eq 'con_lost') { &logthis("Subscribe returned con_lost: $filename"); @@ -292,9 +315,11 @@ sub repcopy { } elsif ($remoteurl eq 'not_found') { &logthis("Subscribe returned not_found: $filename"); return HTTP_NOT_FOUND; - } elsif ($remoteurl eq 'forbidden') { - &logthis("Subscribe returned forbidden: $filename"); + } elsif ($remoteurl eq 'rejected') { + &logthis("Subscribe returned rejected: $filename"); return FORBIDDEN; + } elsif ($remoteurl eq 'directory') { + return OK; } else { my @parts=split(/\//,$filename); my $path="/$parts[1]/$parts[2]/$parts[3]/$parts[4]"; @@ -319,17 +344,55 @@ sub repcopy { ." LWP get: $message: $filename"); return HTTP_SERVICE_UNAVAILABLE; } else { + if ($remoteurl!~/\.meta$/) { + my $mrequest=new HTTP::Request('GET',$remoteurl.'.meta'); + my $mresponse=$ua->request($mrequest,$filename.'.meta'); + if ($mresponse->is_error()) { + unlink($filename.'.meta'); + &logthis( + "INFO: No metadata: $filename"); + } + } rename($transname,$filename); return OK; } } } +# --------------------------------------------------------- Server Side Include + +sub ssi { + + my ($fn,%form)=@_; + + my $ua=new LWP::UserAgent; + + my $request; + + if (%form) { + $request=new HTTP::Request('POST',"http://".$ENV{'HTTP_HOST'}.$fn); + $request->content(join '&', map { "$_=$form{$_}" } keys %form); + } else { + $request=new HTTP::Request('GET',"http://".$ENV{'HTTP_HOST'}.$fn); + } + + $request->header(Cookie => $ENV{'HTTP_COOKIE'}); + my $response=$ua->request($request); + + return $response->content; +} + +# ------------------------------------------------------------------------- Log + +sub log { + my ($dom,$nam,$hom,$what)=@_; + return reply("log:$dom:$nam:$what",$hom); +} + # ----------------------------------------------------------------------- Store sub store { my %storehash=shift; - my $command=; my $namevalue=''; map { $namevalue.=escape($_).'='.escape($storehash{$_}).'&'; @@ -351,7 +414,7 @@ sub restore { my ($name,$value)=split(/\=/,$_); $returnhash{&unescape($name)}=&unescape($value); } split(/\&/,$answer); - return $returnhash; + return %returnhash; } # -------------------------------------------------------- Get user priviledges @@ -362,15 +425,18 @@ sub rolesinit { if (($rolesdump eq 'con_lost') || ($rolesdump eq '')) { return ''; } my %allroles=(); my %thesepriv=(); - my $userroles=''; my $now=time; + my $userroles="user.login.time=$now\n"; my $thesestr; if ($rolesdump ne '') { map { - if ($_!~/rolesdef\&/) { + if ($_!~/^rolesdef\&/) { my ($area,$role)=split(/=/,$_); + $area=~s/\_\w\w$//; my ($trole,$tend,$tstart)=split(/_/,$role); + $userroles.='user.role.'.$trole.'.'.$area.'='. + $tstart.'.'.$tend."\n"; if ($tend!=0) { if ($tend<$now) { $trole=''; @@ -382,19 +448,17 @@ sub rolesinit { } } if (($area ne '') && ($trole ne '')) { - $userroles.='user.role.'.$trole.'.'.$area.'='. - $tstart.'.'.$tend."\n"; my ($tdummy,$tdomain,$trest)=split(/\//,$area); if ($trole =~ /^cr\//) { my ($rdummy,$rdomain,$rauthor,$rrole)=split(/\//,$trole); my $homsvr=homeserver($rauthor,$rdomain); if ($hostname{$homsvr} ne '') { my $roledef= - reply("get:$rdomain:$rauthor:roles:rolesdef&$rrole", + reply("get:$rdomain:$rauthor:roles:rolesdef_$rrole", $homsvr); if (($roledef ne 'con_lost') && ($roledef ne '')) { my ($syspriv,$dompriv,$coursepriv)= - split(/&&/,$roledef); + split(/\_/,unescape($roledef)); $allroles{'/'}.=':'.$syspriv; if ($tdomain ne '') { $allroles{'/'.$tdomain.'/'}.=':'.$dompriv; @@ -458,6 +522,21 @@ sub get { return %returnhash; } +# -------------------------------------------------------------- dump interface + +sub dump { + my $namespace=shift; + my $rep=reply("dump:$ENV{'user.domain'}:$ENV{'user.name'}:$namespace", + $ENV{'user.home'}); + my @pairs=split(/\&/,$rep); + my %returnhash=(); + map { + my ($key,$value)=split(/=/,$_); + $returnhash{unespace($key)}=unescape($value); + } @pairs; + return %returnhash; +} + # --------------------------------------------------------------- put interface sub put { @@ -497,6 +576,9 @@ sub allowed { my ($priv,$uri)=@_; $uri=~s/^\/res//; $uri=~s/^\///; + if ($uri=~/^adm\//) { + return 'F'; + } my $thisallowed=''; if ($ENV{'user.priv./'}=~/$priv\&([^\:]*)/) { $thisallowed.=$1; @@ -515,9 +597,37 @@ sub allowed { sub definerole { if (allowed('mcr','/')) { my ($rolename,$sysrole,$domrole,$courole)=@_; + map { + my ($crole,$cqual)=split(/\&/,$_); + if ($pr{'cr:s'}!~/$crole/) { return "refused:s:$crole"; } + if ($pr{'cr:s'}=~/$crole\&/) { + if ($pr{'cr:s'}!~/$crole\&\w*$cqual/) { + return "refused:s:$crole&$cqual"; + } + } + } split('/',$sysrole); + map { + my ($crole,$cqual)=split(/\&/,$_); + if ($pr{'cr:d'}!~/$crole/) { return "refused:d:$crole"; } + if ($pr{'cr:d'}=~/$crole\&/) { + if ($pr{'cr:d'}!~/$crole\&\w*$cqual/) { + return "refused:d:$crole&$cqual"; + } + } + } split('/',$domrole); + map { + my ($crole,$cqual)=split(/\&/,$_); + if ($pr{'cr:c'}!~/$crole/) { return "refused:c:$crole"; } + if ($pr{'cr:c'}=~/$crole\&/) { + if ($pr{'cr:c'}!~/$crole\&\w*$cqual/) { + return "refused:c:$crole&$cqual"; + } + } + } split('/',$courole); my $command="encrypt:rolesput:$ENV{'user.domain'}:$ENV{'user.name'}:". "$ENV{'user.domain'}:$ENV{'user.name'}:". - "rolesdef&$rolename=$sysrole&&$domrole&&$courole"; + "rolesdef_$rolename=". + escape($sysrole.'_'.$domrole.'_'.$courole); return reply($command,$ENV{'user.home'}); } else { return 'refused'; @@ -527,12 +637,109 @@ sub definerole { # ------------------------------------------------------------------ Plain Text sub plaintext { - return $prp{$_}; + my $short=shift; + return $prp{$short}; } # ----------------------------------------------------------------- Assign Role sub assignrole { + my ($udom,$uname,$url,$role,$end,$start)=@_; + my $mrole; + if ($role =~ /^cr\//) { + unless ($url=~/\.course$/) { return 'invalid'; } + unless (allowed('ccr',$url)) { return 'refused'; } + $mrole='cr'; + } else { + unless (($url=~/\.course$/) || ($url=~/\/$/)) { return 'invalid'; } + unless (allowed('c'+$role)) { return 'refused'; } + $mrole=$role; + } + my $command="encrypt:rolesput:$ENV{'user.domain'}:$ENV{'user.name'}:". + "$udom:$uname:$url".'_'."$mrole=$role"; + if ($end) { $command.='_$end'; } + if ($start) { + if ($end) { + $command.='_$start'; + } else { + $command.='_0_$start'; + } + } + return &reply($command,&homeserver($uname,$udom)); +} + +# ---------------------------------------------------------- Assign Custom Role + +sub assigncustomrole { + my ($udom,$uname,$url,$rdom,$rnam,$rolename,$end,$start)=@_; + return &assignrole($udom,$uname,$url,'cr/'.$rdom.'/'.$rnam.'/'.$rolename, + $end,$start); +} + +# ----------------------------------------------------------------- Revoke Role + +sub revokerole { + my ($udom,$uname,$url,$role)=@_; + my $now=time; + return &assignrole($udom,$uname,$url,$role,$now); +} + +# ---------------------------------------------------------- Revoke Custom Role + +sub revokecustomrole { + my ($udom,$uname,$url,$rdom,$rnam,$rolename)=@_; + my $now=time; + return &assigncustomrole($udom,$uname,$url,$rdom,$rnam,$rolename,$now); +} + +# ------------------------------------------------------------ Directory lister + +sub dirlist { + my $uri=shift; + $uri=~s/^\///; + $uri=~s/\/$//; + my ($res,$udom,$uname,@rest)=split(/\//,$uri); + if ($udom) { + if ($uname) { + my $listing=reply('ls:'.$perlvar{'lonDocRoot'}.'/'.$uri, + homeserver($uname,$udom)); + return split(/:/,$listing); + } else { + my $tryserver; + my %allusers=(); + foreach $tryserver (keys %libserv) { + if ($hostdom{$tryserver} eq $udom) { + my $listing=reply('ls:'.$perlvar{'lonDocRoot'}.'/res/'.$udom, + $tryserver); + if (($listing ne 'no_such_dir') && ($listing ne 'empty') + && ($listing ne 'con_lost')) { + map { + my ($entry,@stat)=split(/&/,$_); + $allusers{$entry}=1; + } split(/:/,$listing); + } + } + } + my $alluserstr=''; + map { + $alluserstr.=$_.'&user:'; + } sort keys %allusers; + $alluserstr=~s/:$//; + return split(/:/,$alluserstr); + } + } else { + my $tryserver; + my %alldom=(); + foreach $tryserver (keys %libserv) { + $alldom{$hostdom{$tryserver}}=1; + } + my $alldomstr=''; + map { + $alldomstr.=$perlvar{'lonDocRoot'}.'/res/'.$_.'&domain:'; + } sort keys %alldom; + $alldomstr=~s/:$//; + return split(/:/,$alldomstr); + } } # -------------------------------------------------------- Escape Special Chars @@ -613,12 +820,9 @@ if ($readit ne 'done') { } } + $readit='done'; &logthis('INFO: Read configuration'); } } 1; - - - -